CVE-2022-45798
Description
A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges by creating a symbolic link and abusing the service to delete a file.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Local privilege escalation vulnerability in Trend Micro Apex One Damage Cleanup Engine via link following, allowing SYSTEM-level code execution.
Vulnerability
A link following vulnerability exists in the Damage Cleanup Engine component of Trend Micro Apex One and Apex One as a Service. The Damage Cleanup Engine runs within the Trend Micro Common Client Real-time Scan Service. By creating a junction (symbolic link), a local attacker can abuse the service to delete a folder. The vulnerability is present in certain versions of the software; specific affected versions are not detailed in available references. [1]
Exploitation
An attacker must first obtain the ability to execute low-privileged code on the target system. Then, by creating a junction pointing to a privileged location, the attacker can cause the Damage Cleanup Engine to delete a folder, which can be leveraged for privilege escalation. No user interaction is required beyond initial low-privilege code execution. [1]
Impact
Successful exploitation allows an attacker to escalate privileges to SYSTEM and execute arbitrary code in the context of SYSTEM. This results in full compromise of confidentiality, integrity, and availability of the affected system. The CVSS v3 score is 7.8 (High). [1]
Mitigation
Trend Micro has released security updates for Apex One and Apex One as a Service. Users should apply the latest patches as provided in the vendor advisory [2]. The advisory URL currently returns an unavailable page; however, it is recommended to check the Trend Micro support site for the appropriate patch information. [2]
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Trend Micro, Inc./Trend Micro Apex Onev5Range: On Premise (14.0)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.